Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2j3f-972q-6fv5

больше 3 лет назад

The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j3f-2fhx-9r3x

почти 4 года назад

Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.

EPSS: Низкий
github логотип

GHSA-2j3c-m8j3-c8j2

больше 3 лет назад

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

EPSS: Низкий
github логотип

GHSA-2j3c-jv49-w6c7

больше 3 лет назад

A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j39-qcjm-428w

около 2 лет назад

Apache Struts vulnerable to path traversal

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2j39-6c38-r3mx

больше 3 лет назад

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.

CVSS3: 7.2
EPSS: Высокий
github логотип

GHSA-2j39-64q5-rjfv

почти 4 года назад

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j38-xhmg-c3g9

больше 3 лет назад

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.

EPSS: Средний
github логотип

GHSA-2j38-pmwm-2h3f

больше 3 лет назад

An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.

EPSS: Низкий
github логотип

GHSA-2j38-64p3-w8wc

5 месяцев назад

A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteuser.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2j38-53q9-crr9

больше 3 лет назад

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j37-h336-4w29

больше 3 лет назад

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

EPSS: Низкий
github логотип

GHSA-2j35-5wj8-vcv8

больше 3 лет назад

Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j33-qvm8-55q5

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor VoucherPress allows Stored XSS. This issue affects VoucherPress: from n/a through 1.5.7.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2j32-c79r-58r7

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2j2x-m8gc-xcrm

больше 3 лет назад

EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump.

EPSS: Низкий
github логотип

GHSA-2j2x-hx4g-2gf4

больше 7 лет назад

In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2j2x-2gpw-g8fm

около 3 лет назад

flat vulnerable to Prototype Pollution

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j2w-j5j7-7cgr

около 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetIsp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2j2w-gm6q-cv65

больше 1 года назад

: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j3f-972q-6fv5

The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j3f-2fhx-9r3x

Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2j3c-m8j3-c8j2

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j3c-jv49-w6c7

A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j39-qcjm-428w

Apache Struts vulnerable to path traversal

CVSS3: 9.8
93%
Критический
около 2 лет назад
github логотип
GHSA-2j39-6c38-r3mx

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.

CVSS3: 7.2
88%
Высокий
больше 3 лет назад
github логотип
GHSA-2j39-64q5-rjfv

The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2j38-xhmg-c3g9

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.

21%
Средний
больше 3 лет назад
github логотип
GHSA-2j38-pmwm-2h3f

An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j38-64p3-w8wc

A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteuser.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2j38-53q9-crr9

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j37-h336-4w29

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

6%
Низкий
больше 3 лет назад
github логотип
GHSA-2j35-5wj8-vcv8

Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2j33-qvm8-55q5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor VoucherPress allows Stored XSS. This issue affects VoucherPress: from n/a through 1.5.7.

CVSS3: 5.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-2j32-c79r-58r7

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2j2x-m8gc-xcrm

EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j2x-hx4g-2gf4

In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode

CVSS3: 7.4
0%
Низкий
больше 7 лет назад
github логотип
GHSA-2j2x-2gpw-g8fm

flat vulnerable to Prototype Pollution

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2j2w-j5j7-7cgr

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetIsp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2j2w-gm6q-cv65

: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу